# How Wallet Data Is Secured Using AES Encryption in Nautilus Wallet

> Learn how Nautilus Wallet secures your data with AES-256 encryption. Your mnemonic seed phrase is protected and decrypted only with your password.

- Repository: [Nautilus Team/nautilus-wallet](https://github.com/nautls/nautilus-wallet)
- Tags: internals
- Published: 2026-03-07

---

**Nautilus Wallet encrypts sensitive mnemonic seed phrases using AES-256 via the crypto-js library before storing them in IndexedDB, decrypting them on-demand only when the user provides the correct password.**

The nautls/nautilus-wallet repository implements client-side cryptographic protection to safeguard cryptocurrency wallet data. Understanding how wallet data is secured using AES encryption reveals the architectural decisions that protect user assets from unauthorized access while maintaining full user control over private keys.

## AES Encryption Architecture in Nautilus Wallet

### The crypto-js Implementation

The wallet leverages the `crypto-js` library to perform symmetric encryption. When a user creates a standard wallet, the application calls `AES.encrypt()` from crypto-js, passing the mnemonic phrase and the user-provided password as parameters. This generates a Base64-encoded ciphertext string that replaces the plaintext mnemonic in storage.

### Key Derivation with EVP_BytesToKey

Under the hood, crypto-js implements the OpenSSL `EVP_BytesToKey` algorithm for key derivation. This process converts the user password into a 256-bit encryption key and a 128-bit initialization vector (IV) using MD5-based iterations. When the password is sufficiently complex, this effectively provides AES-256 encryption strength, ensuring that the encrypted wallet data remains confidential even if the storage medium is compromised.

## Encrypting Wallet Data at Creation

The encryption process occurs in [`src/stores/appStore.ts`](https://github.com/nautls/nautilus-wallet/blob/main/src/stores/appStore.ts) within the `putWallet` function. When persisting a new standard wallet, the application encrypts the mnemonic before it ever touches the database:

```typescript
// src/stores/appStore.ts
import AES from "crypto-js/aes";

const encrypted = AES.encrypt(mnemonic, userPassword).toString();
// encrypted is a Base64 string stored in the wallet record

```

The resulting ciphertext is then passed to `walletsDbService.put()`, which stores the encrypted wallet object in the browser's IndexedDB. Only the mnemonic field receives this treatment; public keys, addresses, and configuration settings remain in plaintext since they do not require confidentiality.

## Decrypting Data on Demand

Retrieval and decryption happen in [`src/database/walletsDbService.ts`](https://github.com/nautls/nautilus-wallet/blob/main/src/database/walletsDbService.ts) through the `getMnemonic` function. This method fetches the encrypted value from IndexedDB and reverses the encryption process:

```typescript
// src/database/walletsDbService.ts
import AES from "crypto-js/aes";
import utf8Enc from "crypto-js/enc-utf8";

const decrypted = AES.decrypt(storedCiphertext, userPassword)
                     .toString(utf8Enc);

if (!decrypted) {
  throw new PasswordError(); // Invalid password or corrupted data
}

```

The function converts the decrypted bytes back to a UTF-8 string. If the user provided an incorrect password, the decryption yields an empty or malformed result, triggering a `PasswordError` that halts any further operations requiring the private key.

### Handling Password Errors

The `PasswordError` exception serves as a critical security control. Defined in the same file (lines 31-36), this error prevents the application from proceeding with transaction signing or address derivation when authentication fails. This ensures that brute-force attempts against the encrypted wallet data cannot silently succeed with garbage output.

## Security Considerations for AES Wallet Encryption

While the AES implementation provides strong cryptographic guarantees, several operational factors affect the real-world security of wallet data:

- **Password strength is paramount**: Since the encryption key derives directly from the user password via EVP_BytesToKey, weak passwords remain vulnerable to offline brute-force attacks against the stored ciphertext. High-entropy passphrases are essential.

- **Local storage only**: The encrypted mnemonic never leaves the device. IndexedDB storage confines the attack surface to local malware or physical device access, eliminating network-based interception risks.

- **Memory exposure**: The password exists only in memory during encryption/decryption operations. The application does not persist authentication credentials, minimizing the window for memory scraping attacks.

- **No plaintext fallback**: Unlike some wallet implementations that maintain encrypted and unencrypted copies, Nautilus Wallet stores only the AES ciphertext. There is no plaintext "backdoor" version of the mnemonic in the database.

## Summary

Nautilus Wallet secures sensitive wallet data using AES encryption through the following mechanisms:

- **AES-256 encryption** via crypto-js protects mnemonic seed phrases before storage in IndexedDB
- **EVP_BytesToKey** derivation converts user passwords into cryptographic keys without storing the password itself
- **On-demand decryption** in `walletsDbService.getMnemonic()` ensures plaintext mnemonics exist only in memory when needed
- **PasswordError exceptions** prevent unauthorized access and protect against brute-force attempts
- **Client-side only** architecture ensures encrypted data never traverses networks or external servers

## Frequently Asked Questions

### What encryption standard does Nautilus Wallet use?

Nautilus Wallet uses **AES (Advanced Encryption Standard)** implemented through the crypto-js library. Specifically, it employs AES-256 when the user provides a sufficiently complex password, as the EVP_BytesToKey derivation generates a 256-bit key from the passphrase.

### Where is the encrypted wallet data stored?

The encrypted wallet data resides in the browser's **IndexedDB** database, specifically within the wallets object store. This client-side storage ensures that sensitive ciphertext never leaves the user's device or transmits over networks, reducing exposure to remote attacks.

### What happens if I forget my password?

If you forget your password, **you cannot recover your wallet**. Since Nautilus Wallet derives the AES encryption key directly from your password using EVP_BytesToKey, and the application never stores the password itself, there is no mechanism to decrypt the stored mnemonic without the original passphrase. You would need to restore the wallet from a backup seed phrase.

### Is the password stored anywhere in the application?

**No**, the password is never persisted to disk or stored in the database. It exists only in volatile memory during the brief moments when encryption or decryption operations occur in `appStore.putWallet()` or `walletsDbService.getMnemonic()`. This design minimizes the risk of password exposure through memory dumps or local storage breaches.